Rethinking OT Security: Why an IT-Centric Approach Falls Short
OT security isn't an IT problem, and treating it like one is where most organisations get it wrong.
Speak to an expert
For decades, operational technology lived in its own world. The systems running factory floors, power grids, and water treatment plants were isolated by design — and that isolation was the security strategy. Nobody outside the building could reach them, so nobody outside the building was the threat.
That world is gone. And in my experience, most security teams haven't caught up with what that actually means.
The convergence happened faster than the mindset changed
IIoT adoption, remote operations, vendor access, cloud connectivity — all of it has quietly connected OT environments to the same internet-facing attack surface that targets every other part of the business. The efficiency gains are real. But so is the exposure.
The biggest risk in OT security isn't a sophisticated attacker. It's a converged network being defended with an unconverged mindset.
What I mean by that: IT security instincts — patch fast, isolate aggressively, prioritise confidentiality — don't translate cleanly into OT environments. When the compromised system controls a production line or a power substation, taking it offline isn't a precaution. It's an operational event. Sometimes a safety one.
Five differences every security leader needs to understand
After more than 25 years delivering OT/IT convergence projects across manufacturing, energy, and critical infrastructure, these are the gaps I see most often:
1. Priority: availability beats confidentiality
In IT, confidentiality comes first. In OT, availability and physical safety are the actual priority. A system going offline can mean a production stoppage or a physical hazard — not just a data risk.
2. Patching: routine vs. high-risk
IT systems follow regular patch cycles. OT equipment often runs on legacy hardware that can't be patched without scheduled downtime — or can't be patched at all without full replacement.
3. Lifespan: years vs. decades
IT hardware refreshes every 3–5 years. OT equipment can remain in operational use for 15–25 years. You're often securing infrastructure that was designed before modern cyber threats existed.
4. Incident response: isolate vs. assess
In IT, isolating a compromised system is the first move. In OT, that same move may require a physical safety assessment first. The wrong response can be more dangerous than the threat itself.
5. Visibility: mature vs. emerging
IT environments generally have solid asset inventory and monitoring. Many OT environments still don't have basic visibility into what's connected to the network — which makes early threat detection significantly harder.

The conversation worth having before an incident forces it
Regulation is catching up — NIS2 now explicitly extends security obligations to operators of essential infrastructure. But compliance isn't the reason to act. The reason to act is that the organisations getting this right aren't bolting IT security tools onto OT networks. They're building a converged security strategy from the ground up, one that respects the different failure modes of each environment.
That's a very different starting point — and it requires a very different conversation.
If you're navigating OT/IT convergence, I'd be interested to hear where the hardest gaps have been in your organisation.


